Bitget Exchange Hit by $351.6 Million Wallet Breach: A Full Breakdown of the Incident

On September 24, 2026, the cryptocurrency world was rocked by the news of a major security breach at Bitget, one of the world's largest centralized exchanges. An estimated $351.6 million in assets was drained from the exchange's wallets in a sophisticated attack that has since been linked to North Korean hackers. This article breaks down the timeline, the aftermath, and what it means for the crypto industry.

The Timeline of the Attack

The breach was first detected on September 24, 2026, at 18:31 UTC. Bitget's security systems flagged unauthorized transfers originating from a portion of its hot and warm wallet infrastructure. The exchange immediately activated its emergency response protocols and suspended all withdrawals as a precautionary measure.

Within approximately one hour, on-chain analysts and security firms began tracking the flow of funds. Roughly $183 million** in various cryptocurrencies had been moved from wallets labeled as Bitget's to a newly created address. A particularly telling sign was that the attacker quickly swapped **$19.67 million in USDT0 for 7,111 ETH in just six minutes via decentralized exchanges, paying a premium of up to 5% above the market rate—a classic indicator of a hacker prioritizing speed over cost.

The Stolen Assets: What Was Taken?

As on-chain investigations continued, the full scope of the theft became clearer. Lookonchain, a prominent on-chain analytics firm, updated the total stolen assets to approximately $356.86 million.

The breakdown of the stolen assets is as follows:

· XRP: 102,926,478 tokens (~$157.48 million) — the largest portion of the stolen funds.

· ETH: 31,890 tokens (~$85.75 million).

· Stablecoins: 34.75 million USDT, 21.05 million USDC, and 19.67 million USD₮0.

· Other Assets: Including 3,000 XAUt (~$12.82 million), 12,719 BNB (~$9.88 million), 821,012 AVAX (~$8.38 million), and 20.59 million TRX (~$7.07 million).

The hacker quickly moved the stolen funds across various chains, consolidating a significant portion into Ethereum. By September 25, the hacker's EVM addresses held approximately 68,500 ETH, valued at roughly $184 million. Additional addresses held the stolen XRP and TRX.

Bitget's Response: "Not the Next FTX"

Bitget CEO Gracy Chen addressed the incident directly in a live AMA, aiming to reassure users. She confirmed that the exchange's cold wallets remained fully secure and that only a portion of the hot and warm wallet layers were affected.

In its official security notice, Bitget stated:

"User funds are safe. The full amount of this loss falls within the coverage of Bitget's User Protection Fund, which currently holds over $464 million".

The exchange confirmed that the entire $351.6 million loss would be covered by its User Protection Fund, ensuring that no user would lose their balances. Withdrawals were temporarily paused but were set to resume after a full security review. Deposits and trading continued to operate normally throughout the incident.

Chen also emphasized that this event does not signal a collapse akin to FTX, stating, "We will not run from this, and every dollar will be accounted for".

How Did the Hack Happen?

According to Bitget's preliminary investigation, the attack was not the result of a private key leak. Instead, the attackers compromised a core backend wallet service and used it to spoof transaction data, tricking the exchange's authorization process into releasing funds.

This method bypassed the need for private keys, allowing the attacker to directly transfer funds off the platform. Investigators are still working to determine the exact entry point, with some reports suggesting a possible third-party software supply chain attack.

Who Is Behind the Attack?

Initial evidence strongly points to the Lazarus Group, a notorious North Korean state-sponsored hacking organization. CEO Gracy Chen noted that some of the IP addresses used by the attackers showed "highly consistent" patterns with VPN services previously used by North Korean hacking groups.

This assessment was supported by several on-chain analysts, including Specter and Conor Grogan, who noted that the attack's timing and methodology align with the Lazarus Group's known tactics. The group has been responsible for numerous high-profile crypto thefts, including the $1.4 billion Bybit hack in 2025 and over half of the $1.1 billion stolen in the first half of 2026 alone.

What Happens Next?

Bitget has commissioned a third-party security team to conduct an independent forensic investigation into the breach. The exchange has promised to publish a full incident report, including a root cause analysis, within 24 hours of the initial notice.

Withdrawals will be restored once all potential security risks have been eliminated. In the meantime, Bitget has urged users to remain calm, assuring them that their account balances are accurate and their assets are protected.

This incident serves as a stark reminder of the risks associated with centralized exchanges. While Bitget's protection fund has mitigated the financial impact for users, the breach underscores the persistent threat posed by sophisticated cybercriminals in the crypto space..